This is a computer translation of the original webpage. It is provided for general information only and should not be regarded as complete nor accurate. Close Disclaimer
Skip to main content
U.S. flag

An official website of the United States government

Dot gov

The .gov means it's official.
Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you're on a federal government site.

Https

The site is secure.
The https:// that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.

Public Summary Report: Virginia Did Not Adequately Secure Its Medicaid Data

This summary report provides an overview of the results of our audit of the information security controls over Virginia's Medicaid Management Information System (MMIS). It does not include specific details of the vulnerabilities that we identified because of the sensitive nature of the information. We determined that Virginia did not adequately secure its Medicaid data and information systems in accordance with Federal requirements. Virginia adopted a security program for its MMIS, but numerous significant system vulnerabilities remained. We have provided more detailed information and recommendations to Virginia so that it can address the issues we identified. The findings listed in this summary report reflect a point in time regarding system security and may have changed since we reviewed these systems.

While we do not identify evidence that we have exploited these vulnerabilities, exploitation we have been resulted in unauthorized access to and disclosure of Medicaid beneficiary data, as well as the disruption of critical Medicaid operations. End of
Translation
Click to Translate text after this point
These vulnerabilities were collectively and, in some cases, individually significant and could have compromised the integrity of Virginia's Medicaid program.

We recommended Virginia improve its Medicaid security program to secure Medicaid data and information systems in accordance with Federal requirements, provide adequate oversight to its contractors, and address the vulnerabilities identified during our audit.

Filed under: Center for Medicare and Medicaid Services